ISO 27701 · GDPR
Most articles answer this one of two ways. Either ISO 27701 makes you GDPR compliant, or it does nothing for GDPR at all. Both are wrong. The real answer sits in three lines of the law.
TL;DR
GDPR is law. ISO 27701 is a standard you opt into. A certificate never makes you compliant. It does give you most of the machinery the law asks for, and a regulator can weigh it. It misses one shortcut, in Articles 24 and 32. That clause names a different kind of certificate.
Sources: GDPR Articles 24, 32 and 42 · EDPB, April 2026
They are not the same kind of thing
The comparison people ask for does not quite exist. One of these is a law. The other is a standard you opt into.
GDPR applies because of what you do and who you do it to. You do not sign up. Offer goods or services to people in the EU, or track them there, and the law reaches you from Toronto or Austin. It reaches you the same way it reaches Dublin. No certificate switches it off.
ISO/IEC 27701 is the opposite. Nobody makes you adopt it. You build a privacy information management system, or PIMS. An accredited body audits it. You get a certificate that says so. Our guide to what ISO 27701 certification is covers how that works.
So the useful question is not which one wins. It is what a certificate buys you under a law that never asked for one.
What the GDPR says about certificates
Read this part with care. The law is far more precise than the marketing around it.
Article 24 puts the duty on you. You have to put the right measures in place. You also have to show that your processing follows the law. Article 32 says the same for security.
Both then offer a shortcut, in the same words.
“Adherence to … approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.”
GDPR Article 24(3)Article 32(3) repeats it for security of processing
Read the middle of that sentence. The shortcut covers mechanisms as referred to in Article 42. Not certificates in general.
Article 42(5) says who may issue one. A body accredited under Article 43, or the supervisory authority itself. Either way it works from criteria that the authority or the European Data Protection Board approved. An ISO certificate comes from a different chain.
Irene Kamara made the point in the IAPP.
“Technical and management standards … including the well-known information security standard ISO/IEC 27001 or the new ISO/IEC 27701 … are not necessarily part of a GDPR certification mechanism.”
Irene KamaraWriting for the IAPP on GDPR certification
One more line matters. Article 42(4) says a certificate does not reduce your responsibility. It also leaves the supervisory authority’s powers untouched. Even the real GDPR seal buys no shield.
Where the “ISO 27701 equals GDPR” claim comes from
The 2019 edition shipped an annex mapping its controls to GDPR articles. A mapping is a study aid. It shows one view of which control answers which article. It judges nothing about your processing, and no regulator adopted it. Vendors turned that annex into a compliance claim. The claim stuck.
What ISO 27701 does cover
Now the useful half. Most of the work GDPR asks for is the work a PIMS makes you do.
| GDPR duty | What a PIMS gives you | Fit |
|---|---|---|
| Records of processing, Article 30 | The records of processing a PIMS is built on | Close |
| Data protection by design and default, Article 25 | An Annex A control group of the same name | Close |
| Data protection impact assessment, Article 35 | Privacy impact assessment, using ISO/IEC 29134 | Close |
| Security of processing, Article 32 | Annex A.3, on the ISO 27001 control set | Close |
| Rights of the data subject, Chapter III | Obligations to PII principals in Annex A | Partial |
| Breach notification, Articles 33 and 34 | Incident handling, but not the 72-hour clock | Partial |
| Lawful basis and consent, Articles 6 and 7 | You record a basis. Nothing tests whether it holds | Gap |
| EU representative, Article 27 | Nothing | Gap |
| International transfers, Chapter V | Nothing on adequacy, clauses or transfer assessments | Gap |
Close means a PIMS artifact answers the article. Gap means the article asks a legal question a management system does not.
Where it leaves you exposed
Look at the bottom three rows, because that is where teams get caught.
A PIMS makes you write down a lawful basis for each activity. It does not tell you whether that basis survives a challenge. Legitimate interest is the usual trap. You record it. An auditor ticks that you recorded it. Nobody weighs it against the rights of the people involved. That test is a legal judgment, and a certificate does not make it.
Transfers are the second. Send EU personal data to a US processor and three questions follow. Adequacy, standard contractual clauses, and a transfer impact assessment. No clause of ISO 27701 answers them.
Then the clock. Article 33 gives you 72 hours to report a personal data breach. Your PIMS will have an incident process. Whether it runs to that deadline, with the right facts, is something you design for. You do not inherit it.
How to use the certificate honestly
ISO 27701 is strong evidence for Article 24(1) and Article 32(1). Those ask you to put the right measures in place and prove it. Say that. It is not evidence under Article 24(3), which names Article 42 mechanisms. A privacy lawyer will notice. So will a good vendor risk reviewer.
If you do need a GDPR certificate
Some buyers do ask for one by name. There is a real answer, and it is not ISO 27701.
Europrivacy holds approval as a European Data Protection Seal. That is the certificate the law describes. The European Data Protection Board approved its criteria, which is what Article 42(5) asks for. In April 2026 the Board went further. It adopted an Opinion recognising those criteria as a tool for transfers. So an importer outside Europe can certify to ease data coming in.
That is the shape of a real Article 42 certificate. Criteria approved by an authority or the Board. Issued by a body accredited under Article 43. Test any claim against those two.
The same logic applies at home
No North American privacy statute treats an ISO certificate as proof either. PIPEDA, Quebec Law 25, Alberta and B.C. PIPA, HIPAA and the US state privacy laws all judge what you do. The certificate shortens the conversation. It does not end it.
Which one you need, and when
Three situations cover almost every team that asks us.
- You serve people in the EU. GDPR applies now. A certificate is a separate question, and it can wait. Fix the lawful bases, the transfer route and the breach process first. Those are the three with a fine attached.
- Your buyers keep sending privacy questionnaires. This is the ISO 27701 case. One certificate from an accredited body answers most of the form. It travels to buyers in any country.
- A buyer asks for GDPR certification by name. Ask what they will accept. Most mean “show me you take this seriously”. ISO 27701 does that. A few mean Article 42, and for those there is one approved seal.
If you are choosing where to start, our guide to designing and implementing a PIMS sets out the order of the work.
Frequently asked questions
Does ISO 27701 make you GDPR compliant?
No. GDPR compliance is a legal state. It turns on what you do with personal data. ISO 27701 certifies a management system. It gives you most of the records, roles and assessments the law expects. That makes compliance easier to reach and easier to show. It does not deliver it.
Is ISO 27701 a GDPR certification under Article 42?
No. Article 42(5) asks for criteria approved by a supervisory authority or the European Data Protection Board. It also asks for a certificate issued by a body accredited under Article 43. ISO runs through a different chain. So the Article 24(3) and 32(3) shortcut does not apply.
Is ISO 27701 useless for GDPR then?
Far from it. Articles 24(1) and 32(1) ask for the right measures, and for proof of them. A certified PIMS is strong evidence of both. It also delivers the records of processing, impact assessments and privacy by design work the law demands. Claim it under those articles, not Article 42.
What is an approved GDPR certification?
Europrivacy holds approval as a European Data Protection Seal. The European Data Protection Board approved its criteria. In April 2026 the Board also recognised those criteria as a tool for transfers. That is what an Article 42 mechanism looks like in practice.
What does ISO 27701 not cover?
The legal judgments. Whether your lawful basis holds up. Whether a legitimate interest test passes. Whether you need an EU representative under Article 27. How you move personal data out of the EU under Chapter V. It also gives you an incident process rather than the 72-hour deadline in Article 33.
Does a certificate reduce a GDPR fine?
Article 42(4) is plain. A certificate does not reduce your responsibility, and it leaves the supervisory authority’s powers untouched. What you have done to protect people does count when an authority weighs a penalty. A certificate is part of that picture rather than a discount.
Key takeaways
- GDPR is law and reaches you by what you do. ISO 27701 is a voluntary standard you choose to adopt.
- Articles 24(3) and 32(3) let an approved certificate help show compliance. Only one named in Article 42 counts.
- ISO 27701 fails that test. Article 42(5) needs criteria approved by an authority or the EDPB.
- It is still strong evidence under Articles 24(1) and 32(1), which ask for the right measures and proof of them.
- Records of processing, impact assessments, privacy by design and security map well between the two.
- Lawful basis, transfers and the 72-hour breach clock are the gaps. All three carry the real penalty risk.
- If a buyer wants a genuine GDPR certificate, Europrivacy is the approved European Data Protection Seal.
Work out what your buyers will accept
The answer decides whether you need a certificate, a legal review, or both. Talk to us about ISO 27701 readiness and where privacy law sits alongside it.